CVE-2026-42514

Severity CVSS v4.0:
HIGH
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
29/04/2026
Last modified:
29/04/2026

Description

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs.<br /> <br /> Successful exploitation of this vulnerability could allow an attacker to impersonate the target user and gain unauthorized access to user accounts on the targeted system.